Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 4 min 96 bronnen 2 kritiek 28 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2014-1692

HIGH · 7.3 CVSS Gepubliceerd: CWE-119

Beschrijving

The hash_buffer function in schnorr.c in OpenSSH through 6.4, when Makefile.inc is modified to enable the J-PAKE protocol, does not initialize certain data structures, which might allow remote attackers to cause a denial of service (memory corruption) or have unspecified other impact via vectors that trigger an error condition.

Vendors

Openbsd

Affected products

Openssh

References